Google Trust Services: New hire onboarding deviation from written procedure
Google Trust Services (GTS) reported that, during a new hire onboarding process, some access control group memberships were granted in a different order than their documented procedures specify. GTS stated this resulted from multiple process deviations, including that access control group membership and the access ticket were handled after training but before the examination was completed, and that a team manager approved an access ticket type that should have been approved by the Policy Authority (PA). GTS said there was no impact to certificate issuance or validation, and that controls prevented premature access to CA systems because access required both access control group grants and a configuration deployment, with access gated by Multi-Party Authorization (MPA). GTS investigated and prepared an incident report, then implemented remediation changes to improve sequencing and reduce manual steps, including revising the process so the exam proctor files post-exam access requests, re-evaluating and reducing steps/approvals/systems, and simplifying onboarding sequencing. GTS later reported that automation for access group membership management was tested and is active, and that training process improvements were completed. The bug was resolved as FIXED, with GTS stating all action items were completed and requesting closure.
- GTS identified an onboarding process deviation during new hire access provisioning and opened an incident report in the CA Program bug tracker.
- GTS published the incident report describing the deviations, impact assessment, and planned remediation.
- GTS reported completion of one scheduled action item by revising the access request process so the exam proctor files post-exam access requests.
- GTS reported completion of remaining action items, including access automation and training process improvements, and requested bug closure.
- Google representative — GTS reported that new hire access group membership was granted in a different order than procedures specify, and said it would prepare an incident report and publish it by 2024-11-22.
- Google representative — GTS posted the incident report, stating training was complete but the examination was not completed before access control group membership and related approvals occurred, and described the current process, deviations, impact (no certificate issuance/validation impact), and investigation findings.
- Google representative — GTS requested setting the "Next update" field to 2024-12-06 for the next AI update.
- Google representative — GTS reported it revised the access request procedure so the exam proctor files post-exam access requests, and said additional improvements were continuing with further updates planned.
- Google representative — GTS reported completion of remaining action items, including reducing manual steps, testing and activating automation for access group membership, and improving the training process, and requested closure if no further comments.
- Mozilla representative — Mozilla requested a brief closing summary including incident description, root causes, remediation, any commitments, and confirmation that all action items were completed.
- Google representative — GTS provided the requested closure summary, stating the root cause was onboarding complexity and sequencing with insufficient controls to enforce the documented procedure, and that three remediation changes were implemented with no additional ongoing commitments beyond completed action items.
- Google representative — GTS requested the bug be closed if there were no further questions or comments.